Post-Quantum Cryptography
Post-Quantum Cryptography (PQC) refers to a new generation of encryption methods designed to protect information against the potential future threat of attacks from quantum computers. Because quantum computers could eventually break many of the cryptographic protections in use today, PQC aims to provide algorithms that remain secure even against that capability. It is generally described as a defense measure rather than a guarantee, and specific approved algorithms continue to evolve.
Post-Quantum Cryptography (PQC) is the development and deployment of cryptographic algorithms intended to withstand cryptanalytic attacks by both classical and future quantum computers. According to NIST, PQC algorithms are based on mathematical problems believed to be resistant to quantum attack, distinguishing them from classical public-key schemes vulnerable to quantum algorithms. NIST's PQC project leads the national and global standardization effort to secure electronic information against the anticipated quantum threat, while CISA's PQC Initiative coordinates government and industry partners to address the associated security and migration risks. This entry covers the concept only; readers should verify the current set of standardized or recommended PQC algorithms, applicable federal migration guidance, and specific implementation or authorization requirements against current official NIST and CISA sources, as this terminology and the associated standards continue to evolve.
Why it matters
Much of the public-key cryptography protecting government and defense information today relies on mathematical problems that a sufficiently capable quantum computer could eventually solve. NIST describes post-quantum cryptography as a defense against potential cyberattacks from quantum computers, meaning the concern is anticipatory: the goal is to migrate to quantum-resistant algorithms before a practical quantum threat materializes, rather than after data has already been exposed. This forward-looking posture matters because encrypted information can be captured and stored now for potential decryption later once quantum capability arrives.
For defense and public sector organizations, the significance is amplified by the long lifecycle and high sensitivity of protected data. NIST's PQC project is positioned as leading the national and global effort to secure electronic information against the future quantum threat, and CISA's PQC Initiative brings government and industry partners together to address the associated security and migration risks. These parallel efforts signal that PQC is treated as a coordinated, cross-sector migration challenge, not a single product or one-time fix.
Because the standards and the set of approved algorithms continue to evolve, treating PQC as a settled requirement would be a mistake. PQC is generally described as a defense measure rather than a guarantee, and adopting an algorithm does not by itself constitute compliance or security. Organizations should track current NIST standards and CISA migration guidance rather than assuming that any particular algorithm selection is final or that quantum resistance eliminates the need for broader cryptographic and system-level controls.
Who it's relevant to
Inside PQC
Common questions
Answers to the questions practitioners most commonly ask about PQC.